cbcvebase.
CVE-2020-8286
published 2020-12-14

CVE-2020-8286: curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.

high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
applemac_os_x< 10.14.610.14.6
applemac_os_x
applemac_os_x
applemac_os_x>= 10.15 < 10.15.710.15.7
applemacos>= 11.0 < 11.311.3
applemacos_big_sur
applesecurity_update_2021-002_catalina
debiancurl< curl 7.74.0-1 (bookworm)curl 7.74.0-1 (bookworm)
debiandebian_linux
debiandebian_linux
fedoraprojectfedora
fedoraprojectfedora
haxxcurl>= 0 < 7.74.0-17.74.0-1
haxxcurl>= 0 < 7.74.0-17.74.0-1
haxxcurl>= 0 < 7.74.0-17.74.0-1
haxxcurl>= 0 < 7.74.0-17.74.0-1
haxxcurl>= 0 < 7.47.0-1ubuntu2.187.47.0-1ubuntu2.18
haxxcurl>= 0 < 7.58.0-2ubuntu3.127.58.0-2ubuntu3.12
haxxcurl>= 0 < 7.68.0-1ubuntu2.47.68.0-1ubuntu2.4
haxxlibcurl>= 7.41.0 < 7.74.07.74.0
httpsgithub.com_curl_curl
msrccm1_curl_7.68.0-3_on_cbl_mariner_1.0
oraclecommunications_billing_and_revenue_management
oraclecommunications_cloud_native_core_policy
oracleessbase

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
osv7.5HIGH